Back to Headlines
AnalysisCrypto

SafePal order-data breach exposes 39,798 customers, but keys and funds are untouched

An authorization flaw in an order-tracking plug-in exposed names, addresses and contact details. Seed phrases, private keys and crypto holdings were not affected — the residual risk is phishing.

Editorial visual: 39,798 customer order records were exposed; wallet keys, seed phrases and funds were not.
Editorial illustrationEditorial visual: 39,798 customer order records were exposed; wallet keys, seed phrases and funds were not.

Hardware-wallet provider SafePal has disclosed a security incident that exposed the personal information of tens of thousands of customers, while leaving wallet credentials and crypto holdings intact.

The exposed data included names, physical addresses and contact details, putting affected users at risk of phishing and impersonation attempts. The breach did not compromise any cryptocurrency funds, passwords or private wallet keys.

SafePal said on Sunday that it had identified an "authorization flaw" in a plug-in used to track customer orders. The flaw likely allowed attackers to view other customers' orders — the equivalent of a shop's parcel-tracking system letting one customer read another's receipt and delivery details simply by changing the order number.

The breach affected 39,798 customers who placed orders between March 2, 2025 and April 11, 2026.

The company stressed that the core security of its wallets remains intact, adding that users' seed phrases, private keys, bank passwords, bank account information, payment card numbers and government-issued identification were not affected.

What the breach exposed against what SafePal said was unaffected, with the company's stated response.
Editorial illustrationWhat the breach exposed against what SafePal said was unaffected, with the company's stated response.

There is one important exception on the user side. SafePal said customers who have already shared their private keys or seed phrases in response to a phishing email, phone call or letter should treat that wallet as compromised and move their assets to a new one.

SafePal said it had patched the vulnerability and introduced additional security measures. It notified all affected customers by email on Sunday and engaged an independent third-party security firm to audit the fix and review its order-processing systems. The company also said it would retain customers' personal data in that order-processing system for only 90 days from collection, and that it had identified and removed more than 30 fraudulent websites and phishing links associated with the breach. Customers can use a verification tool on SafePal's website to check whether their own data was affected.

The incident follows a recent compromise of Coldcard hardware wallets, in which the attacker reportedly took at least $120 million in bitcoin. The two events are different in kind — one exposed order records, the other took funds — and they do not by themselves indicate a systemic weakness in hardware wallets. Taken together, though, they support the case for assessing concentration risk and, where appropriate, spreading holdings across more than one wallet.